Recently Viewed Topics
Change the Location of the Elasticsearch Database
If the primary volume where the Elasticsearch database is installed doesn't have enough space to store the event rate, you can use another higher capacity volume to store the LCE 5.x Elasticsearch DB.
These steps illustrate how to change the location of the Elasticsearch DB.
Create a base directory at the new location.
# mkdir /<volume>/ES/
Backup the /etc/elasticsearch/elasticsearch.yml file.
# cp -v /etc/elasticsearch/elasticsearch.yml /tmp
Stop the LCE service.
Stop the Stats Daemon.
# service stats stop
Stop the Elasticsearch service.
# service elasticsearch stop
Copy data to the new directory you created in Step 1.
# mv -v /opt/lce/db/ <yourNewDbPath>Caution: This operation may take a significant amount of time depending on the size of your database.
Update LCE with the path to the new Elasticsearch location.
# /opt/lce/tools/es-helper-scripts/move-activeDb <absolute path of new_dbDir>Note: This script will also start the Elasticsearch instance.
Start the LCE service.
Display the current log directory location.
# /opt/lce/tools/lce_cfg_utils --display database-directory
Verify new events are stored in Elasticsearch at its new location.
Get the current silo number:
# curl 'http://<LCEServerIP>:9200/_cat/indices'
Query the data in the current silo. The current silo will be the one with the highest number.
The example below assumes the current silo is 8.
# curl 'http://<LCEServerIP>:9200/silo8/events/_search?size=20&pretty'
Current logs/events should be returned by the query.